Configure UEBA
UEBA Overview
UEBA in Director Console is a security solution that helps you configure UEBA in Fabric-enabled LogPoint. It helps you manage potential breaches efficiently and provides you with the tools to analyze the detected anomalies.
UEBA dashboard includes License, Overview, Entity Selection, and Settings.You can set a proper baseline in UEBA which requires a minimum of 30 days of historical data. If you want to enable UEBA today, you need appropriately normalized and enriched input logs of at least 30 days.
You can enable UEBA, add the UEBA license, and select the repos and entities for UEBA analysis from the UEBA page. You can also view the health status of the system.
Managing UEBA Entities
You can access the Entity Selection page only after uploading the license and enabling UEBA.
You can add, edit, and delete the entities for UEBA to monitor on the Entity Selection page. It shows:
The total number of licensed entities.
The total number of entities set for threat analysis.
The specifics of the configured entities.
The total number of users and machines chosen.
Configuring UEBA Settings
You can choose the LogPoint Search Head and Distributed LogPoint instances repositories for UEBA analysis in Fabric-enabled LogPoint instances from the Settings page. Similarly, you can enable or disable the history service.
Last updated
Was this helpful?


















